8. Anti-Forensic Guarantees

  • Kernel compiled with CONFIG_DEBUG_INFO=n, CONFIG_STRIP_ASM_SYMS=y

  • No crash dumps (kernel.panic_on_oops=1, kernel.panic=1)

  • /proc/kcore masked with custom eBPF hook

  • All USB devices detached 50 ms before TraceKill™

  • HDMI framebuffer zeroed (prevents screen burn recovery)

  • TPM PCRs extended with random values on every boot (destroys measured boot evidence)

Last updated